AWS Security ChangesHomeSearch

AWS ebs: EBS volume copy encryption and cross-account sharing

Service: ebs · 2026-09-27 · Documentation medium

File: ebs/latest/userguide/ebs-copying-volume.md · Type: encryption

Summary

Expanded EBS volume copy documentation to cover cross-account copies via AWS RAM, encryption behavior for encrypted/unencrypted sources, KMS key requirements, and CLI examples for encrypting/re-encrypting copies.

Security assessment

The change documents encryption behavior and cross-account KMS key sharing for EBS volume copies, including that default AWS managed keys cannot be shared/copied across accounts. It is security guidance rather than a fix for a specific vulnerability.

Evidence

+Volumes encrypted with the default AWS managed key for Amazon EBS can't be shared or copied across accounts.

Diff

diff --git a/ebs/latest/userguide/ebs-copying-volume.md b/ebs/latest/userguide/ebs-copying-volume.md
index 16310be38..0e472fda6 100644
--- a//ebs/latest/userguide/ebs-copying-volume.md
+++ b//ebs/latest/userguide/ebs-copying-volume.md
@@ -11 +11,3 @@ InitializationEncryptionConsiderationsPricingCopy a volume
-You can create an instant point-in-time copy of an Amazon EBS volume within the same Availability Zone. A volume copy begins as a crash-consistent, point-in-time copy of the source volume. It includes all the data blocks written to the source volume at the time the volume copy initialization begins. The volume copy gets its own unique volume ID. Volume copies are created immediately and can be attached to an Amazon EC2 instance once it reaches the `available` state. Using volume copies, you can quickly copy your production data for test and development environments.
+A volume copy is a crash-consistent, point-in-time copy of the source volume. It includes all the data blocks written to the source volume at the time the volume copy initialization begins. The volume copy gets its own unique volume ID. Volume copies are created immediately and can be attached to an Amazon EC2 instance once it reaches the `available` state. Using volume copies, you can quickly copy your production data for test and development environments.
+
+You can also create copies from volumes shared with you by other AWS accounts. To copy a volume from another account, the source volume must be shared with you through AWS Resource Access Manager (AWS RAM). For more information, see [Share a volume](./share-volume.html).
@@ -19 +21 @@ Volume copies are initialized after creation. During initialization, the data bl
-Copy operations do not affect the performance of the source volume. You can continue using the source volume normally during the copy process. Copied volumes can be accessed instantly without waiting for the data to be copied from the source volume. Volume copies provide instant access to data with single-digit millisecond latency, however, actual latency might vary depending on the volume type. During initialization, the volume copy delivers **baseline performance** equal to the lowest of the following three values:
+Copy operations don't affect the performance of the source volume. You can continue using the source volume normally during the copy process. Copied volumes can be accessed instantly without waiting for the data to be copied from the source volume. Volume copies provide instant access to data with single-digit millisecond latency. However, actual latency might vary depending on the volume type. During initialization, the volume copy delivers **baseline performance** equal to the lowest of the following three values:
@@ -21 +23 @@ Copy operations do not affect the performance of the source volume. You can cont
-  * 3,000 IOPS and 125 MiB/s
+  * 3,000 input/output operations per second (IOPS) and 125 MiB/s
@@ -51 +53,42 @@ You can monitor the initialization progress using the [describe-volume-status](h
-Copies of encrypted volumes are automatically encrypted with the same KMS key as the source volume. You can't copy unencrypted volumes.
+When you copy a volume, the encryption of the copy depends on the encryption state of the source volume, your account's encryption by default setting, and the `Encrypted` and `KmsKeyId` parameters you specify in the copy request.
+
+### Unencrypted source volumes
+
+If the source volume is unencrypted and encryption by default is disabled for your account, the copy is unencrypted. You can encrypt the copy by setting the `Encrypted` parameter to `true`. If you don't specify a KMS key, your account's default Amazon EBS encryption key is used.
+
+If the source volume is unencrypted and encryption by default is enabled for your account, the copy is automatically encrypted. If you don't specify a KMS key, your account's default Amazon EBS encryption key is used.
+
+### Encrypted source volumes
+
+If the source volume is encrypted, the copy is always encrypted. You can't create an unencrypted copy from an encrypted source volume.
+
+For same-account copies, the copy uses the same KMS key as the source volume by default. You can specify a different customer managed key to re-encrypt the copy.
+
+For cross-account copies, the copy uses your account's default Amazon EBS encryption key by default. You can specify a different customer managed key in the `KmsKeyId` parameter. You can use the source account's KMS key to encrypt the volume copy if that key has been shared with your account.
+
+### Cross-account encryption requirements
+
+To copy a shared volume that is encrypted with a customer managed key, the volume owner must share the KMS key with your account. For more information, see [Allowing users in other accounts to use a KMS key](https://docs.aws.amazon.com/kms/latest/developerguide/key-policy-modifying-external-accounts.html) in the AWS Key Management Service Developer Guide.
+
+Volumes encrypted with the default AWS managed key for Amazon EBS can't be shared or copied across accounts.
+
+### Encryption outcomes
+
+Unencrypted source volumes Encryption by default | You specify a KMS key | Result  
+---|---|---  
+Disabled | No | Copy is unencrypted  
+Disabled | Yes | Copy encrypted with the specified key  
+Enabled | No | Copy encrypted with your account's default Amazon EBS encryption key  
+Enabled | Yes | Copy encrypted with the specified key  
+  
+Encrypted source volumes (same-account) You specify a KMS key | Result  
+---|---  
+No | Copy encrypted with the same key as the source volume  
+Yes | Copy re-encrypted with the specified key  
+  
+Encrypted source volumes (cross-account) You specify a KMS key | Result  
+---|---  
+No | Copy encrypted with your account's default Amazon EBS encryption key  
+Yes | Copy encrypted with the specified key  
+  
+Cross-account copies never reuse the source account's KMS key by default. If you want to use a key from the source account, it must be shared with your account.
@@ -55 +98 @@ Copies of encrypted volumes are automatically encrypted with the same KMS key as
-  * You can create copies from encrypted source volumes only. You can't create copies from unencrypted source volumes.
+  * A volume copy captures a crash-consistent, point-in-time state of the source volume. It includes only the data that has been written to the volume at the time of the copy request. It doesn't include data cached by applications or the operating system. To achieve application-consistent copies, pause writes to the volume or quiesce the application before creating the copy. For databases, use the appropriate mechanism to flush dirty pages and freeze I/O (such as `fsfreeze` on Linux or VSS on Windows). You can resume writes after the copy request returns.
@@ -73 +116 @@ Copies of encrypted volumes are automatically encrypted with the same KMS key as
-  * Tags assigned to the source volume are not assigned to the volume copy.
+  * Tags assigned to the source volume aren't assigned to the volume copy.
@@ -82 +125 @@ Copies of encrypted volumes are automatically encrypted with the same KMS key as
-When creating a clone of a source volume, you are charged for the clone operation. The clone operation charge is based on the size of the data blocks written to the source volume at the time of clone creation. The newly created volume is charged the same way as any other Amazon EBS volume. For more information, see [Amazon EBS pricing](https://aws.amazon.com/ebs/pricing/).
+When you create a copy of a source volume, you are charged for the copy operation. The copy operation charge is based on the size of the data blocks written to the source volume at the time of copy creation. The newly created volume is charged the same way as any other Amazon EBS volume. For more information, see [Amazon EBS pricing](https://aws.amazon.com/ebs/pricing/).
@@ -109 +152 @@ Console
-  9. (_Optional_) To assign custom tags to the volume copy, in the **Tags** section, choose **Add tag** , and then enter a tag key and value pair.
+  9. For **Encryption** , the default depends on the source volume and your account settings. For same-account copies, the copy inherits the source volume's encryption key. For cross-account copies, your account's default Amazon EBS encryption key is used. You can choose a different customer managed key.
@@ -111 +154 @@ Console
-  10. Choose **Copy volume**.
+  10. (_Optional_) To assign custom tags to the volume copy, in the **Tags** section, choose **Add tag** , and then enter a tag key and value pair.
@@ -113 +156,3 @@ Console
-  11. The copied volume enters the `creating` state and then transitions to `available` shortly after. You can then attach it to an Amazon EC2 instance in the same Availability Zone.
+  11. Choose **Copy volume**.
+
+  12. The copied volume enters the `creating` state and then transitions to `available` shortly after. You can then attach it to an Amazon EC2 instance in the same Availability Zone.
@@ -133,0 +179,19 @@ The following example creates a volume copy of `vol-01234567890abcdef` with the
+###### To encrypt an unencrypted volume during copy
+
+Use the copy-volumes command with the `--encrypted` and `--kms-key-id` parameters.
+    
+    
+    aws ec2 copy-volumes \
+    --source-volume-id vol-01234567890abcdef \
+    --encrypted \
+    --kms-key-id alias/my-key
+
+###### To re-encrypt with a different customer managed key
+
+Use the copy-volumes command with the `--kms-key-id` parameter to specify a different key.
+    
+    
+    aws ec2 copy-volumes \
+    --source-volume-id vol-01234567890abcdef \
+    --kms-key-id arn:aws:kms:us-east-1:222222222222:key/abcd1234-a123-456a-a12b-a123b4cd56ef
+
@@ -149,0 +214,19 @@ The following example creates a volume copy of `vol-01234567890abcdef` with the
+###### To encrypt an unencrypted volume during copy
+
+Use the Copy-EC2Volume cmdlet with the `-Encrypted` and `-KmsKeyId` parameters.
+    
+    
+    Copy-EC2Volume `
+    -SourceVolumeId vol-01234567890abcdef `
+    -Encrypted $true `
+    -KmsKeyId "alias/my-key"
+
+###### To re-encrypt with a different customer managed key
+
+Use the Copy-EC2Volume cmdlet with the `-KmsKeyId` parameter to specify a different key.
+    
+    
+    Copy-EC2Volume `
+    -SourceVolumeId vol-01234567890abcdef `
+    -KmsKeyId "arn:aws:kms:us-east-1:222222222222:key/abcd1234-a123-456a-a12b-a123b4cd56ef"
+
@@ -156 +239 @@ To use the Amazon Web Services Documentation, Javascript must be enabled. Please
-Create a volume
+Share a volume